CVE-2025-9660: SourceCodester Bakeshop Online Ordering System passwordrecover.php sql injection
A vulnerability was found in SourceCodester Bakeshop Online Ordering System 1.0. The impacted element is an unknown function of the file /passwordrecover.php. Performing manipulation of the argument phonenumber results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9660?
CVE-2025-9660 is considered to have a high severity due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-9660?
To fix CVE-2025-9660, sanitize and validate user inputs in the /passwordrecover.php file to prevent SQL injection.
What software is affected by CVE-2025-9660?
CVE-2025-9660 affects the SourceCodester Bakeshop Online Ordering System version 1.0.
Can CVE-2025-9660 be exploited remotely?
Yes, CVE-2025-9660 can be exploited remotely by manipulating the phonenumber argument.
What is the attack vector for CVE-2025-9660?
The attack vector for CVE-2025-9660 is an SQL injection vulnerability in the /passwordrecover.php file.